FETCHUB – AI RSS Feed Aggregator & Translator Security & Risk Analysis

wordpress.org/plugins/fetchub

Fetch, translate, and publish RSS feeds automatically with AI.

20 active installs v1.3.8 PHP 7.4+ WP 6.0+ Updated Unknown
aggregatoraifeedrsstranslator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FETCHUB – AI RSS Feed Aggregator & Translator Safe to Use in 2026?

Generally Safe

Score 100/100

FETCHUB – AI RSS Feed Aggregator & Translator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The fetchub plugin v1.3.8 demonstrates a generally good security posture, with strong adherence to best practices in many areas. The plugin extensively uses prepared statements for its SQL queries (97%) and performs adequate output escaping on most of its output (79%). It also includes a healthy number of nonce and capability checks (23 and 22 respectively), indicating an effort to secure its entry points.

However, there are a few areas that warrant attention. The analysis revealed one REST API route that lacks permission callbacks, presenting a potential entry point for unauthorized access if not properly secured by the application context. Furthermore, the taint analysis identified one flow with unsanitized paths, which could lead to issues if the data influencing this path originates from user input and is not thoroughly validated. The presence of a file operation and external HTTP requests also increases the attack surface slightly, though no immediate vulnerabilities are indicated by the provided data.

The plugin's vulnerability history is currently clear, with no recorded CVEs. This is a positive sign, suggesting that the plugin has either been well-developed or has not yet been a target for widespread exploitation. However, the absence of past vulnerabilities does not guarantee future security, and the identified code signals should still be addressed. Overall, fetchub v1.3.8 is a relatively secure plugin, but the identified unprotected REST API route and unsanitized path flow are specific risks that require remediation.

Key Concerns

  • Unprotected REST API route without permission callback
  • Taint flow with unsanitized path
  • Some output not properly escaped
Vulnerabilities
None known

FETCHUB – AI RSS Feed Aggregator & Translator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FETCHUB – AI RSS Feed Aggregator & Translator Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
28 prepared
Unescaped Output
67
255 escaped
Nonce Checks
23
Capability Checks
22
File Operations
1
External Requests
11
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

97% prepared29 total queries

Output Escaping

79% escaped322 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
<class-translator> (includes\class-translator.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

FETCHUB – AI RSS Feed Aggregator & Translator Attack Surface

Entry Points15
Unprotected1

AJAX Handlers 14

authwp_ajax_fetchub_update_ai_modelincludes\class-translator.php:682
authwp_ajax_fetchub_fetch_allincludes\class-translator.php:683
authwp_ajax_fetchub_stop_allincludes\class-translator.php:684
authwp_ajax_fetchub_stop_feedincludes\class-translator.php:685
authwp_ajax_fetchub_logs_listincludes\class-translator.php:686
authwp_ajax_fetchub_logs_clearincludes\class-translator.php:687
authwp_ajax_fetchub_save_log_toggleincludes\class-translator.php:688
authwp_ajax_fetchub_save_settingsincludes\class-translator.php:689
authwp_ajax_fetchub_cron_listincludes\class-translator.php:690
authwp_ajax_fetchub_cron_run_nowincludes\class-translator.php:691
authwp_ajax_fetchub_cron_deleteincludes\class-translator.php:692
authwp_ajax_fetchub_cron_rescheduleincludes\class-translator.php:693
authwp_ajax_fetchub_cron_healthincludes\class-translator.php:694
authwp_ajax_fetchub_uninstall_cleanupincludes\class-translator.php:695

REST API Routes 1

GET/wp-json/fetchub/v1/authorization/revokeincludes\class-tk.php:73
WordPress Hooks 28
actionplugins_loadedfetchub.php:33
actioninitfetchub.php:70
actionupgrader_process_completefetchub.php:81
actionload-toplevel_page_fetchubincludes\admin-hooks.php:26
filtercron_schedulesincludes\admin-hooks.php:43
actionadmin_post_fetchub_export_settingsincludes\admin-hooks.php:84
actionadmin_post_fetchub_download_logsincludes\admin-hooks.php:127
actionadmin_post_fetchub_import_settingsincludes\admin-hooks.php:186
actionadmin_post_fetchub_revoke_licenseincludes\admin-hooks.php:254
actionadmin_menuincludes\admin-hooks.php:279
actioninitincludes\admin-hooks.php:286
actionsave_postincludes\admin-hooks.php:338
actionwp_trash_postincludes\admin-hooks.php:346
actionbefore_delete_postincludes\admin-hooks.php:350
filtermanage_edit-post_columnsincludes\admin-hooks.php:422
actionmanage_post_posts_custom_columnincludes\admin-hooks.php:449
actionfetchub_weekly_cleanupincludes\admin-hooks.php:611
actionrest_api_initincludes\class-tk.php:52
actionadmin_initincludes\class-translator.php:671
actionadmin_initincludes\class-translator.php:672
actionadmin_enqueue_scriptsincludes\class-translator.php:673
actionadmin_menuincludes\class-translator.php:674
filtercron_schedulesincludes\class-translator.php:675
actionplugins_loadedincludes\class-translator.php:676
actionfetchub_weekly_cleanupincludes\class-translator.php:677
actionfetchub_feed_cronincludes\class-translator.php:680
filtercron_schedulesincludes\class-translator.php:1264
filtercron_schedulesincludes\class-translator.php:1596

Scheduled Events 11

fetchub_feed_cron
fetchub_feed_cron
fetchub_weekly_cleanup
fetchub_weekly_cleanup
fetchub_feed_cron
fetchub_feed_cron
fetchub_feed_cron
fetchub_weekly_cleanup
fetchub_feed_cron
fetchub_feed_cron
fetchub_feed_cron
Maintenance & Trust

FETCHUB – AI RSS Feed Aggregator & Translator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads949

Community Trust

Rating100/100
Number of ratings4
Active installs20
Developer Profile

FETCHUB – AI RSS Feed Aggregator & Translator Developer Profile

Unioney

3 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FETCHUB – AI RSS Feed Aggregator & Translator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fetchub/includes/css/fetchub-admin.css/wp-content/plugins/fetchub/includes/js/fetchub-admin.js
Script Paths
/wp-content/plugins/fetchub/includes/js/fetchub-admin.js
Version Parameters
fetchub/includes/css/fetchub-admin.css?ver=fetchub/includes/js/fetchub-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
fetchub-translator-settings
HTML Comments
<!-- FETCHUB AI Aggregator & Translator Settings -->
Data Attributes
data-ai-delay
JS Globals
Fetchub_Admin
FAQ

Frequently Asked Questions about FETCHUB – AI RSS Feed Aggregator & Translator